Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.
April 05, 2024ISC StormCast for Friday, April 5th, 2024Slicing up DoNex with Binary Ninjahttps://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812 HTTP/2 Continuation Floodhttps://nowotarski.info/http2-continuation-flood-technical-details/ Dangers of CSS in HTML Emailhttps://lutrasecurity.com/en/articles/kobold-letters/ Dan Mazella: Infostealers in Automotive Headunitshttps://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/...more16minPlay
April 04, 2024ISC StormCast for Thursday, April 4th, 2024Playing with xzbot: Some things you can learn from SSH traffichttps://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/ Google Proposes Device Bound Session Credentials (DBSC)https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html Four More Ivanti Vulnerabilitieshttps://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US Google Pixel Zero Dayhttps://source.android.com/docs/security/bulletin/pixel/2024-04-01...more7minPlay
April 04, 2024ISC StormCast for Thursday, April 4th, 2024Playing with xzbot: Some things you can learn from SSH traffichttps://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/ Google Proposes Device Bound Session Credentials (DBSC)https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html Four More Ivanti Vulnerabilitieshttps://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US Google Pixel Zero Dayhttps://source.android.com/docs/security/bulletin/pixel/2024-04-01...more7minPlay
April 03, 2024ISC StormCast for Wednesday, April 3rd, 2024Chrome Incognito Mode Settlementhttps://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/ Google E-Mail Sender Guidelines FAQhttps://support.google.com/a/answer/14229414?hl=en&fl=1&sjid=2270464422796374445-NC Cisco Updates and VPN Best Practiceshttps://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.htmlhttps://sec.cloudapps.cisco.com/security/center/publicationListing.x Apache Pulsar Vulnerabilityhttps://pulsar.apache.org/security/CVE-2024-29834/ Progress Flowmon Network Monitoring Tool Vulnerability CVE-2024-2389https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability Wait Just an Infosec Episode with Bojan Zdrnja: Thursday April 4th 2024 10:00 EDSThttps://isc.sans.edu/j/xzutils (link will redirect once episode is live)...more6minPlay
April 03, 2024ISC StormCast for Wednesday, April 3rd, 2024Chrome Incognito Mode Settlementhttps://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/ Google E-Mail Sender Guidelines FAQhttps://support.google.com/a/answer/14229414?hl=en&fl=1&sjid=2270464422796374445-NC Cisco Updates and VPN Best Practiceshttps://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.htmlhttps://sec.cloudapps.cisco.com/security/center/publicationListing.x Apache Pulsar Vulnerabilityhttps://pulsar.apache.org/security/CVE-2024-29834/ Progress Flowmon Network Monitoring Tool Vulnerability CVE-2024-2389https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability Wait Just an Infosec Episode with Bojan Zdrnja: Thursday April 4th 2024 10:00 EDSThttps://isc.sans.edu/j/xzutils (link will redirect once episode is live)...more6minPlay
April 02, 2024ISC StormCast for Tuesday, April 2nd, 2024The amazingly scary xz sshd backdoorhttps://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802 The xz-utils backdoor in security advisories by national CSIRTshttps://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800 Checking CSV Fileshttps://isc.sans.edu/diary/Checking%20CSV%20Files/30796 Infostealers Pose Threat to macOShttps://www.jamf.com/blog/infostealers-pose-threat-to-macos/...more8minPlay
April 02, 2024ISC StormCast for Tuesday, April 2nd, 2024The amazingly scary xz sshd backdoorhttps://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802 The xz-utils backdoor in security advisories by national CSIRTshttps://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800 Checking CSV Fileshttps://isc.sans.edu/diary/Checking%20CSV%20Files/30796 Infostealers Pose Threat to macOShttps://www.jamf.com/blog/infostealers-pose-threat-to-macos/...more8minPlay
April 01, 2024ISC StormCast for Monday, April 1st, 2024xz-utils Backdoor CVE-2024-3094https://www.openwall.com/lists/oss-security/2024/03/29/4https://tukaani.org/xz-backdoor/https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 Backdoor reverse analysishttps://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b YARA Rulehttps://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar Social Engineering Attempts to Include Backdoor in Distroshttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708https://news.ycombinator.com/item?id=39866275 Github Repo (now disabled)https://github.com/tukaani-project/xz Statements from Distributionshttps://www.kali.org/blog/about-the-xz-backdoor/https://archlinux.org/news/the-xz-package-has-been-backdoored/https://access.redhat.com/security/cve/CVE-2024-3094https://bugs.gentoo.org/928134https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024...more8minPlay
April 01, 2024ISC StormCast for Monday, April 1st, 2024xz-utils Backdoor CVE-2024-3094https://www.openwall.com/lists/oss-security/2024/03/29/4https://tukaani.org/xz-backdoor/https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 Backdoor reverse analysishttps://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b YARA Rulehttps://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar Social Engineering Attempts to Include Backdoor in Distroshttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708https://news.ycombinator.com/item?id=39866275 Github Repo (now disabled)https://github.com/tukaani-project/xz Statements from Distributionshttps://www.kali.org/blog/about-the-xz-backdoor/https://archlinux.org/news/the-xz-package-has-been-backdoored/https://access.redhat.com/security/cve/CVE-2024-3094https://bugs.gentoo.org/928134https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024...more8minPlay
March 29, 2024ISC StormCast for Friday, March 29th, 2024From JavaScript to AsyncRAThttps://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788 TeamCity Patcheshttps://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&version=2024.03 Okta Verify for Windows Auto-update Arbitrary Code Execution CVE-2024-0980https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/ Google Zero Day Reporthttps://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf...more6minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.